Jump to content

Draft:Feroot Security

From Wikipedia, the free encyclopedia
  • Comment: 12 of the 18 references do not link to that specific article, they just point to the main page of that website. Please fix these too before resubmitting again. AstrooKai (Talk) 18:46, 29 April 2025 (UTC)

Feroot Security
Company typePrivate company
IndustryCybersecurity
Founded2017; 8 years ago (2017)
FoundersIvan Tsarynny, Vitaliy Lim
HeadquartersToronto, Canada
Area served
  • Worldwide
  • North America
  • Europe
  • Asia-Pacific
Key people
Ivan Tsarynny (CEO), Vitaliy Lim (CTO)
Products
  • PaymentGuard AI
  • HealthData Shield AI
  • AlphaPrivacy AI
  • CodeGuard AI
Services
  • Client-side security
  • JavaScript threat detection
  • Web compliance automation
  • Privacy risk analysis
Websitewww.feroot.com


Feroot Security is a Canadian cybersecurity company founded in 2017 that develops tools to detect and mitigate client-side security threats in web applications. Its software monitors browser-based activity to support compliance with data protection regulations including the Payment Card Industry Data Security Standard (PCI DSS), the Health Insurance Portability and Accountability Act (HIPAA), and the General Data Protection Regulation (GDPR). Feroot’s platform is designed to automate compliance workflows, generate audit-friendly reports, and assist with enforcement of security policies aligned with global privacy and data protection standards.

History

[edit]

The company was established in 2017 by Ivan Tsarynny and Vitaliy Lim in response to the growing incidence of client-side security threats associated with JavaScript-heavy websites. In 2024, Feroot began incorporating artificial intelligence to enhance its platform's threat detection and compliance monitoring capabilities. The company has since released a range of products targeting various regulatory frameworks. Feroot’s approach uses AI-powered behavioral analysis to monitor JavaScript activity, detect anomalies, and support non-intrusive deployment without requiring code modifications.

Leadership

[edit]

Ivan Tsarynny

[edit]

Ivan Tsarynny is the CEO and co-founder of Feroot Security. He has participated in public discussions and briefings related to digital security risks, including providing testimony[1] before a U.S. congressional body in 2025 regarding the potential misuse of web tracking technologies. His views have been cited by various media organizations.

Vitaliy Lim

[edit]

Vitaliy Lim is the Chief Technology Officer of Feroot Security. He leads the company’s technical development, drawing on a background in secure web application development. He has contributed to the development of Feroot’s proprietary detection methods for monitoring potentially malicious browser-side code.

Products and Services

[edit]

Feroot’s product suite includes:

  • PaymentGuard AI[2]: A solution aimed at helping businesses comply with PCI DSS requirements by protecting payment data from client-side threats.
  • HealthData Shield AI[3][4]: A tool focused on supporting HIPAA compliance by safeguarding health-related data exposed through web interactions.
  • AlphaPrivacy AI[5]: Software designed to assist with compliance under various international privacy laws such as GDPR and CCPA by identifying and monitoring unauthorized data access.
  • CodeGuard AI: A monitoring system that detects potential code modifications and script injections, helping organizations maintain software integrity.

These tools are intended to help organizations manage client-side risks and protect sensitive data processed via web applications.

Regulatory Compliance Focus

[edit]

PCI DSS

[edit]

Feroot Security’s solutions are designed to address specific requirements of the Payment Card Industry Data Security Standard (PCI DSS). For example, its tools support Requirement 6.4.3, which involves reviewing custom code changes to identify vulnerabilities, and Requirement 11.6.1, which calls for mechanisms to detect unauthorized changes to web content. Feroot’s platform provides monitoring capabilities that help organizations track browser-side activity to detect unauthorized scripts or code injections targeting payment data fields.

HIPAA

[edit]

Feroot’s technology is also used by healthcare providers and vendors to support compliance with the Health Insurance Portability and Accountability Act (HIPAA). The platform focuses on detecting client-side risks that could lead to exposure of Protected Health Information (PHI), particularly via unauthorized JavaScript behavior on patient portals or healthcare websites. These capabilities are aligned with the HIPAA Security Rule's requirements for technical safeguards such as access control, audit controls, and integrity monitoring.

Technology

[edit]

Feroot uses a combination of real-time script analysis, AI-driven threat detection, and behavioral pattern recognition. Its system learns typical script behaviors and flags deviations that could signal security risks. These capabilities are applied to help ensure compliance with several data protection standards, including GDPR, HIPAA, and PCI DSS.

DeepSeek Research

[edit]

In early 2025, Feroot published research documenting the presence of tracking code in the DeepSeek AI application, which it claimed was transmitting data to servers associated with China Mobile. The findings were reported by major news outlets and discussed in governmental forums in the United States and Canada. A detailed review of the platform and its implications for national security was also provided by the United States House Select Committee on the CCP.[6] Feroot’s role in this discovery was covered by media including ABC News[7], the Associated Press[8], CNBC[9], The Independent[10], Yahoo Finance[11], and The Wall Street Journal[12].

References

[edit]
  1. ^ https://www.uscc.gov/sites/default/files/2024-02/Ivan_Tsarynny_Testimony.pdf Testimony of Ivan Tsarynny before the U.S.–China Economic and Security Review Commission, U.S.-China Economic Review Commission
  2. ^ Feroot Security Launches PaymentGuard AI for PCI DSS 4.0 Compliance, EIN Presswire. 15 February 2025.
  3. ^ Feroot Security Launches HealthData Shield AI to Protect ePHI and Ensure HIPAA Compliance, EIN Presswire. 25 January 2025.
  4. ^ Feroot Security Debuts HealthData Shield AI at HIMSS 2025, EIN Presswire. 11 March 2025.
  5. ^ Feroot Launches AlphaPrivacy AI, Automating Global Privacy Compliance, EIN Presswire. 5 March 2025.
  6. ^ DeepSeek and the CCP’s Digital Reach, U.S. House Select Committee on the CCP. April 2025.
  7. ^ DeepSeek’s Coding Capability Could Transfer Users’ Data Directly to China, ABC News. 5 February 2025.
  8. ^ DeepSeek AI Raises Security Concerns Over Chinese Ties, Associated Press. 5 February 2025.
  9. ^ DeepSeek’s Authentication System Is Connected to China, CNBC. 5 February 2025.
  10. ^ DeepSeek AI Can Collect Data for China, Experts Warn, The Independent. 5 February 2025.
  11. ^ DeepSeek’s Advanced Tracking Technology ‘Never Seen Before’, Yahoo Finance. 5 February 2025.
  12. ^ Lawmakers Push to Ban DeepSeek App from U.S. Government Devices, The Wall Street Journal. 5 February 2025.